html-erd-explorer
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions for the agent to generate standalone HTML artifacts for database visualization based on user-provided schemas.
- [SAFE]: The skill explicitly instructs the agent to follow security best practices to prevent XSS: 'Never set innerHTML from a string that includes a variable, user input, computed value, or imported data — it's an XSS vector'. It mandates using
textContentandcreateElementinstead. - [SAFE]: The skill enforces a minimal attack surface by requiring artifacts to be self-contained, forbidding the use of external runtimes, CDNs, or npm packages, with a limited exception for Google Fonts.
- [SAFE]: No patterns of prompt injection, data exfiltration, obfuscation, or unauthorized command execution were detected. The skill's behavior is consistent with its stated purpose of schema documentation.
Audit Metadata